2 ms·
There's certainly some overlap in functionality - both Snort and Bro support signature-based detections. This type of detection has been around since the 90's a
by grigorescu 12y ago
There's certainly some overlap in functionality - both Snort and Bro support signature-based detections. This type of detection has been around since the 90's and while it works, it has many limitations.
If you have high-quality signatures and detections, Bro will do a great job of protecting your network. It has automation capabilities, so it can e-mail the system administrator about a suspicious download, or even reach out to your firewall and block an IP that's scanning you.
However, Bro makes the important assumption that regardless of how good your detections are, you will miss something. A new 0-day will come out, a chain of seemingly innocuous events will be combined in such a way that results in a compromise, etc. To deal with this, Bro tries to log as much as it can (within reason), so that in the event of a compromise, you can go back and see what a particular host did.
For example, when you visit this page, Bro might log something like:
1) 1.2.3.4 issued a DNS A query for news.ycombinator.com and received a response of 198.41.190.47 with a TTL of 300.
2) 1.2.3.4 issued an HTTP GET request for / and received a response of 200 OK
3) 1.2.3.4 downloaded a file over HTTP named index.html with a MD5 of X and a SHA1 of Y
The extra capabilities this provides is evident when a new attack becomes public. With Snort, you would add a new detection, and would receive alerts going forward. With Bro, you can also ask the question "Have I been attacked with this before?" A good example is the APT1 report from Mandiant which listed suspected Chinese hacker IPs, domain names, SSL certs, etc. All that information is stored in the Bro logs, which enables you to do some post-hoc analysis.
There's a ton of other functionality that I'm ignoring. Examples include: a Turing-complete scripting language for writing complex detections, an intelligence framework to watch for suspicious e-mails, IPs, domains, files, etc. and a files framework which can extract certain file types and send them to other tools for additional analysis.
There was a good write-up comparing the two: http://jshlbrd.blogspot.com/2014/04/methods-of-alerting-in-snort-and-bro.html http://jshlbrd.blogspot.com/2014/04/methods-of-alerting-in-s...